NEW: Block one ASN, disrupt sixteen malware families.
OMEGATECH (AS202412) — a three-month-old bulletproof hosting network with 18 /24 prefixes (4,608 IPs). One subnet alone hosts 67 C2 servers:
Remcos (6,562 sightings), AsyncRAT (4,379), Amadey, Latrodectus, XWorm, Stealc, DCRat, LOBSHOT, Eye Pyramid, Mirai, Bashlite, Quasar, ClearFake, SectopRAT, SuperShell, SheetRAT.
Seychelles .sc abuse contact. Pfcloud UG transit. Zero legitimate traffic.
We recovered an Amadey credential stealer plugin (cred64.dll) targeting Chrome, Firefox, Outlook, Thunderbird, FileZilla, WinSCP, and Monero wallets.
3 YARA 10 Suricata on GitHub.
Full writeup:
intel.breakglass.tech/post/o…
h/t
@Fact_Finder03